artifactory vulnerability

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

Published 27 Jul 2026Updated 11 Sep 20262 sources
CVSS 8.1

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.